LEX Risk Management Coach
Lockbase Cyber · Cybersecurity & IT
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 7 captures on record
What the publisher says
As described on Microsoft Marketplace.
Lockbase Exposure Agent (LEX = Lockbase EXposure) is a pre-breach risk-reduction agent that surfaces standing, reducible escalation-path preconditions across Microsoft Entra ID, on-premises Active Directory, and Azure inside Security Copilot, helping CISOs and security teams find and cut the attack paths an adversary would use before exploitation — rather than waiting for an alert and triaging after the fact.
Inputs: Microsoft Defender Advanced Hunting telemetry (identity, sign-in, audit/CloudAppEvents, Exposure Management graph, vulnerability/TVM, device, and AI-agent tables), Microsoft Graph Secure Score, read-only Microsoft Entra and Intune context, and analyst natural-language prompts (a topic such as "how is my Active Directory environment looking", an account UPN, a service-principal or application name, a device name, or a request for a risk scorecard).
Show the rest of the publisher’s description (8 more lines)
Tasks: Surfaces standing, reducible escalation-path preconditions across identity and high-impact exposure by orchestrating 61 risk-reduction skills (60 Advanced Hunting KQL skills plus one Microsoft Graph Secure Score skill) — Entra application and service-principal attack paths, on-prem Active Directory privileged access and Kerberos/NTLM footprint, standing access to crown-jewel assets (Key Vaults, domain controllers, sensitive storage and SQL, Tier-0 systems), cross-subscription privilege blast radius, sign-in / Conditional Access / MFA gaps, AI-agent identity over-privilege, exploitable vulnerabilities and end-of-life software (with CVE, CVSS, and remote-code-execution context) on internet-facing or crown-jewel assets, mailbox delegation, external mail forwarding, SharePoint/OneDrive sharing exposure, and endpoint supply-chain risk. It maps each scoped question to the right skills, ranks findings P1–P4, down-ranks expected access (Microsoft first-party service principals and by-design Active Directory Tier-0 admin groups) to informational, and routes configuration hygiene to Microsoft Secure Score rather than duplicating it. It is risk reduction, not attack detection, and is not a general CVE catalog.
Outputs: Prioritized (P1–P4) risk findings presented worst-first as structured lists, each with the risk level, the escalation path and why it matters (the BloodHound/AzureHound-style standing edge to cut), and the specific reduction action (right-size, remove, harden, retire, or move to PIM-eligible just-in-time). Findings name the actionable identifiers — Entra object and application IDs, host names, source IPs, and asset names — with the precise access verb (for example "WRITE / OWNER access to a named domain controller" or "MONITORING / LOGGING WRITE to a Key Vault"), and route tenant configuration posture to Microsoft Secure Score.
Lockbase Exposure Agent consumes approximately 0.3–1.5 SCU per run, depending on review depth:
- A rapid risk scorecard (one token-capped probe per category across the full estate) runs at ~0.3–0.5 SCU.
- A single-category deep-dive that runs the 5–6 highest-priority skills for one area (for example Entra application attack paths or sign-in/MFA gaps) averages ~0.6–1.0 SCU.
- A broad, multi-category review, or a deep dive that includes one of the heavier Microsoft Exposure Management graph skills (crown-jewel standing access, cross-subscription blast radius, inherited or group-inherited access), reaches ~1.0–1.5 SCU.
- An exposure-graph skill that scans the full identity/resource graph adds ~0.2 SCU per skill beyond the lightweight behavioral and sign-in queries.
- SCU consumption scales with the number of skills invoked, how many risk categories are deep-dived, and the size of the Exposure Management graph and Advanced Hunting tables scanned during each run.
Preview
5 imagesAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Plans and pricing as listed
1 listedSources
Publisher resources
2 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.






